Captive portal or WiFi password for guest WiFi? Security compared
Venue owners often frame guest WiFi as a choice: put a password on it, or put a sign-in page in front of it. The two answer different questions. A password decides who can join the network and encrypts what they send over the air. A captive portal decides what a guest has to do before reaching the internet, and tells the venue who they are. This guide compares the two on security, convenience and what the venue learns, then sets out a configuration that gets the benefits of both.
It is written for owners and the installers who advise them, and the security claims come from the IETF standard for Enhanced Open, the Wi-Fi Alliance and Apple's documentation, listed at the end.
A password and a portal do different jobs
| Job | Shared password (WPA2 or WPA3 Personal) | Captive portal |
|---|---|---|
| Keeps people off the network | Anyone without the password | Nobody; anyone can join and see the page |
| Encrypts traffic over the air | Yes | No, unless the network also uses Enhanced Open or a password |
| Tells the venue who connected | No | Yes, whatever the page asks for |
| Records accepted terms and marketing consent | No | Yes |
| Limits access to paying customers | Only while the password stays private | Yes, with voucher codes or paid passes |
| Effort for the guest | Find and type the password | Complete the page once per session |
The password works at the radio layer and the portal works above it, at the web layer, so a network can have either, both or neither. The guide to WPA3 and Enhanced Open covers the encryption standards themselves in more depth.
What a shared password protects, and what it does not
A password keeps passers-by off the network and encrypts each device's traffic over the air. On a guest network, though, everyone gets the same password. It goes on a chalkboard, a table card or a receipt, it is shared with friends, and after a few weeks it is effectively public. Changing it means telling every regular and reprinting every card.
On WPA2-Personal, the shared password also limits the privacy it gives. RFC 8110 explains that with a shared key, a passive attacker who knows it can "observe the 4-way handshake and compute the traffic encryption keys" for another device. On a network where the password is printed on the wall, that is anyone in the room with the right tools. WPA3-Personal improves on this; the Wi-Fi Alliance says its users "receive increased protections from password guessing attempts". Either way, a password tells the venue nothing about who joined.
What an open network with a portal exposes
An open network has no password, so traffic between each phone and the access point is not encrypted on the radio link. In practice, most of what guests do still travels encrypted end to end, because websites and apps use HTTPS. What remains visible on a plain open network is the traffic that is not encrypted at a higher layer, such as plain HTTP pages and, on many devices, DNS lookups.
The portal does not change any of that. What it adds is a record of who joined, their accepted terms and, if they chose, their marketing consent. That is the case for an open guest network with a portal: guests get online without hunting for a password, and the venue gets a list. Enhanced Open removes most of the encryption gap.
Enhanced Open: encryption without a password
Enhanced Open is the Wi-Fi Alliance name for Opportunistic Wireless Encryption, defined in RFC 8110 in 2017. Each device agrees its own key with the access point as it joins, so traffic is encrypted over the air with nothing to type. The Wi-Fi Alliance describes it as "unauthenticated data encryption" with "no public passphrases to maintain, share, or manage". It protects against passive eavesdropping, including someone who knows the network's name and sits in the corner capturing traffic.
RFC 8110 provides "encryption of the wireless medium but no authentication", so Enhanced Open cannot prove that the access point is the venue's own, and the standard warns that it "is susceptible to an active attack in which an adversary impersonates an access point". A captive portal runs on Enhanced Open exactly as it does on an open network, and older devices that do not support it can join through transition mode where your hardware offers it. On 6 GHz, plain open networks are not allowed at all, so a guest network broadcast on the 6 GHz band of Wi-Fi 6E or Wi-Fi 7 equipment needs Enhanced Open or WPA3.
The threats that matter on guest WiFi
| Threat | Who it affects | What helps |
|---|---|---|
| Someone capturing traffic over the air | Guests | Enhanced Open or WPA3 on the guest network; HTTPS covers most traffic regardless |
| A fake hotspot with the venue's name and a lookalike sign-in page | Guests | A portal that never asks for passwords to other accounts; signage with the exact network name |
| One guest reaching another guest's device | Guests | Client isolation on the guest network |
| A guest reaching the tills, cameras or office computers | The venue | A separate staff network on its own VLAN, with its own password |
| One guest using all the bandwidth | Everyone | A per-guest bandwidth limit and a session length |
| Non-customers using the WiFi from outside | The venue | Voucher codes, or a shorter session length |
A shared password helps with only the first row, and only until it leaks. Most of the protection on a guest network comes from separating it from everything else and isolating guests from each other, which works whether or not there is a password.
How the choice affects returning guests
Phones identify themselves to each network with a private MAC address in place of the hardware one. Apple's guide to private Wi-Fi addresses says an iPhone chooses a Fixed address by default on networks with WPA2 or stronger security, and a Rotating one, which changes every two weeks, on networks with weak or no security. Apple's security guide adds that Rotating is the default for "OWE, WEP, captive portals, and open networks".
So adding a password to a guest network that has a portal does not keep a regular's iPhone on one address: expect it to change every two weeks either way, and the guest to be asked to sign in again after it does. For a venue with a portal this matters less than it sounds, because the guest is identified by the email address or phone number they enter, which does not change. It does explain why some regulars see the sign-in page more often than others.
A setup that covers both
Most venues are best served by two networks, configured differently.
| Guest network | Staff network | |
|---|---|---|
| Security | Enhanced Open where your hardware supports it, otherwise open | WPA3-Personal, or WPA2/WPA3 where older devices need it |
| Captive portal | Yes | No |
| Client isolation | On | Off, so staff devices and printers can reach each other |
| VLAN | Its own, with internet access only | Its own, with access to the tills and office systems |
| Bandwidth | A per-guest limit | No limit, or a generous one |
| Who uses it | Guests | Staff, tills, card machines, printers and venue TVs |
Devices that have to sit on the guest network but cannot complete a portal, such as a TV guests cast to, can be pre-authorised by MAC address; the guide to Chromecast and smart TVs on guest WiFi covers that. Card machines belong on the staff network or their own, following your payment provider's guidance.
When a password on the guest network makes sense
A password on top of a portal can suit a small holiday let or a meeting room, where the password goes in the welcome information and the host still wants the sign-in page for terms and contact details. The trade-off is one more step for every guest, and a password that spreads beyond the people it was meant for.
The setup to avoid is a guest network with a password and no portal running alongside a portal network. Staff hand out the password because it is quicker, guests join the network with no portal, and the venue loses both the terms record and the guest list.
Running it on CaptiFi
CaptiFi's portal runs above the encryption layer, so it works the same on open, Enhanced Open and WPA2 or WPA3 guest networks; the setup guide for your hardware covers where each setting lives. In my.captifi.io you set the WiFi network name, the session length and the guest bandwidth limit for each venue under My Locations, Edit site. Bandwidth limits are not yet enforced on TP-Link Omada, Cisco Meraki or cloud-only UniFi, and a network name change is pushed only to CaptiFi devices and UniFi controllers. Guests sign in with an email address or a phone number on your branded form, and a returning device is let straight through while its address stays the same.
The hardware page lists the ten ecosystems CaptiFi runs on and the plug-and-play device for venues without compatible kit. Plans start from $69/mo on the pricing page, and you can try it on your own network with a 30-day free trial.
Sources: IETF RFC 8110, Opportunistic Wireless Encryption (March 2017); Wi-Fi Alliance, Wi-Fi security; Apple Support, Use private Wi-Fi addresses on Apple devices, and Apple Platform Security, Wi-Fi privacy with Apple devices; CaptiFi's customer documentation and its guide to WPA3 and Enhanced Open, October 2026. Wi-Fi, WPA3 and Enhanced Open are trade marks of the Wi-Fi Alliance; CaptiFi is not affiliated with or endorsed by it.
Frequently asked questions
Quick answers to the most common questions about this topic.
Is a captive portal more secure than a WiFi password?
Is guest WiFi with a captive portal encrypted?
What is Enhanced Open and does it work with a captive portal?
Should guest WiFi have a password?
What is client isolation on guest WiFi?
Can a captive portal run on a password-protected network?
The CaptiFi Editorial Team writes about guest WiFi marketing, captive portals, GDPR-compliant data capture, and local SEO for venue operators. We base our recommendations on real customer outcomes and verified third-party reviews from G2.com.
Ready to turn your guest WiFi into a marketing engine?
CaptiFi captures customer data from every WiFi login, automates Google reviews and email follow-ups, and plugs into the tools you already use. Hardware included (refundable deposit), transparent pricing, 30-day free trial.